Jan 5, 2018

Intel says widespread vulnerability won't slow future chips

Ina Fried, author of Login

A sticker advertising the use of an Intel processor used inside a laptop in London. Photo by Yui Mok/PA Images via Getty Images

Despite the revelation of a massive vulnerability affecting more than a decade's worth of chips, Intel says it believes it has the issue well in hand, both for current and future chips.

Why it matters: For the issue not to hit the bottom line, as Intel maintains it won't, the chipmaker needs to keep current customers happy, maintain its market share and ensure future products don't suffer big delays.

In an interview, two of Intel's top technical leaders told Axios that mitigations are place for all three known vulnerabilities and insists it already has a plan in place to protect future chips. (For more on the chip issues, see this explainer.)

Fixes coming: Initial reports suggested the chip problem was exclusively Intel's issue, that systems can't be fully patched and that even those that could be patched would see a substantial performance hit. But Intel insists none of those three things are true.

  • "We have in place complete mitigations for all three variants," VP Donald Parker told Axios. The company said Thursday that it has firmware updates for half the chips made in the last five years and will have mitigations for 90 percent of those chips by the end of next week.
  • "We will continue to work on products older than that," Parker said, though at a certain point the company says it will gauge demand to figure out how far back to offer fixes.

Performance concerns overblown: While there can be specific instances where the necessary updates slow performance, Intel reiterated that typical users shouldn't see much of a performance impact and pointed to comments from Google, Microsoft and others that seem to bear that out.

Future chips not impacted: Parker said that the company has been designing upcoming chips with changes that will help protect against attacks without giving up entirely on "speculative execution", the technology at the heart of the vulnerability.

  • That's important because speculative execution has proven to be an important technique for making the best use of a chip's processing power.
  • The technique lets chips use excess computing power to essentially play what-if — calculating next steps that might or might not be called for later.
  • Giving up the technique entirely would likely result in slower performance since the chips would spend more time idle.

Making the changes, Parker said, shouldn't cause any significant delays or product cancellations. He said the techniques used to protect against the vulnerability in the new products will be more efficient than the software-based mitigations being used to secure existing ones.

But, but but: Intel says it has been looking around for other, similar vulnerabilities. So far it hasn't found any, but Intel fully expects that outside researchers will be studying if other types of attacks can be crafted using the recently revealed vulnerabilities.

"That's what they do," says Intel corporate VP Stephen Smith.

Stock sale: Also Intel CEO Brian Krzanich is facing renewed scrutiny over millions of dollars of stock sales made last year, after Intel was made aware of the vulnerabilities.

Go deeper

Updated 1 hour ago - Health

World coronavirus updates

Data: The Center for Systems Science and Engineering at Johns Hopkins; Map: Axios Visuals

The number of deaths from the novel coronavirus surpassed 400,000 worldwide on Sunday morning, per Johns Hopkins.

By the numbers: Almost 6.9 million people have tested positive for COVID-19 globally and more than 3 million have recovered from the virus. The U.S. has reported the most cases in the world with over 1.9 million.

George Floyd updates

Protesters gather north of Lafayette Square near the White House during a demonstration against racism and police brutality, in Washington, D.C. on Saturday evening. Photo: Jose Luis Magana/AFP via Getty Images

Tens of thousands of demonstrators have been rallying in cities across the U.S. and around the world to protest the killing of George Floyd. Huge crowds assembled in Washington, D.C., Philadelphia and Chicago for full-day events on Saturday.

Why it matters: Twelve days of nationwide protest in the U.S. has built pressure for states to make changes on what kind of force law enforcement can use on civilians and prompted officials to review police conduct. A memorial service was held for Floyd in Raeford, North Carolina, near where he was born. Gov. Roy Cooper ordered all flags to fly at half-staff to honor him until sunset.

Updated 3 hours ago - Politics & Policy

Coronavirus dashboard

Illustration: Sarah Grillo/Axios

  1. Global: Total confirmed cases as of 3 a.m. ET: 6,898,613 — Total deaths: 399,832 — Total recoveries — 3,087,714Map.
  2. U.S.: Total confirmed cases as of 3 a.m. ET: 1,920,061 — Total deaths: 109,802 — Total recoveries: 500,849 — Total tested: 19,778,873Map.
  3. Public health: Why the pandemic is hitting minorities harder — Coronavirus curve rises in FloridaHow racism threatens the response to the pandemic Some people are drinking and inhaling cleaning products in attempt to fight the virus.
  4. Tech: The pandemic is accelerating next-generation disease diagnostics — Robotics looks to copy software-as-a-service model.
  5. Business: Budgets busted by coronavirus make it harder for cities to address inequality Sports, film production in California to resume June 12 after 3-month hiatus.
  6. Education: Students and teachers flunked remote learning.